BackupProof

Changelog

What changed in each release. BackupProof follows semantic versioning.

0.1.1

Security

  • Windows: the built-in server’s protection of its own data folder could be bypassed with an 8.3 short path (such as C:\PROGRA~3\…) to a folder that doesn’t exist yet, for example when choosing a storage location. Paths are now resolved through their deepest existing folder before comparing.

Download 0.1.1

0.1.0

First release.

Added

  • Install: one-line installers for Linux, macOS and Windows that verify the download, install a service and print the address and a one-time setup code. Re-running upgrades in place; --uninstall removes it. Docker images for the dashboard and the agent.
  • Backups: an encrypted, deduplicating storage format (FastCDC, keyed BLAKE3, XChaCha20-Poly1305, Argon2id) on a local disk, S3-compatible storage with Object Lock, or SFTP. Sources: files, PostgreSQL, MySQL/MariaDB, MongoDB, SQLite and commands, with logins read from Docker containers and WordPress settings.
  • Restore tests in isolated sandboxes: content-root comparison of the restored files, database integrity checks, row-count reconciliation, SQL checks, and loading PostgreSQL dumps found inside backups into a test database.
  • Proofs: signed in-toto/DSSE statements, a hash-chained append-only ledger, RFC 3161 timestamps, offline-verifiable bundles and proof reports mapped to SOC 2, ISO 27001, NIST CSF, DORA, NIS2 and HIPAA.
  • Dashboard: plain-language setup, a built-in “This server”, one-line installs for other servers, discovery of what to protect, dark mode, keyboard and screen-reader support.
  • Import of existing backups: GPG, OpenSSL and age-encrypted files in buckets or folders, restic, Kopia, BorgBackup, and cloud drives via rclone.
  • Releases: every version publishes binaries for Linux, macOS and Windows (amd64 and arm64), checksums, the installers and Docker images.

Security

  • A one-time setup code protects creating the first admin account from other machines on the network.
  • Restores are confined to the restore folder and create symbolic links last, so a crafted backup can’t write files outside it.
  • Restore tests only restore the backup named in a verified proof from that item’s own server, and check its content root first.
  • Anything that could give control of a server is admin-only.
  • The built-in server never backs up, imports from or stores into its own data folder.